Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62jr-f896-9v4h

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

EPSS

Процентиль: 41%
0.00193
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
почти 12 лет назад

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

EPSS

Процентиль: 41%
0.00193
Низкий

Дефекты

CWE-94